basicsecurity.net
Proof, not just disclosure.
Threats / Contributors / Zero Day Initiative
Research org contributor

Zero Day Initiative

cited as evidence in 8 · CNA assigner on 6 (independent) · credited finder on 45 of 57 known-exploited records. Every aggregate on this page is recomputed from the records listed below — each one already cited to its public source.

zerodayinitiative.com ↗ · home of the cited advisories

Independent CNA
57
records cited in
deterministic count
45
finder / reporter credits
CVE.org credits
6
CVE records catalogued (CNA)
independent
58%
avg modeled exploit prob.
FIRST EPSS, 57/57
51%
ransomware-associated
29 of 57 · CISA flag
R

Roles across the work

— find / fix / exploit / catalog, computed per record from credit type, the vendor-self-CNA gate, and the linked public exploit catalog
43
Find
record(s)
0
Fix
record(s)
1
Exploit
record(s)
6
Catalog
record(s)

Part of the Trend Micro family — a hard rollup: this sub-unit’s work aggregates under Trend Micro.

Each dimension is a count of the listed records where this contributor did that job. A CNA row is fix only when the affected product is the assigner’s own; registries, coordinators, platforms, intel and research houses read as catalog, never fix. Exploit counts records where this contributor is credited as author of a public exploit / detection template in a linked catalog — we link the catalog, never host a payload.

01

Known for

— recomputed from this contributor’s own records
SurfacesOperating system / kernel (19), Application / other (17), Server / web platform (14), Hypervisor / virtualization (3), Browser (2)
WeaknessPath traversal / file (10), Injection (9), Memory safety (8), Authentication (8), Authorization / access control (4)
PortfolioMicrosoft (39), Progress (3), VMware (2), TP-Link (2), PaperCut (2), InduSoft (1)
PeopleNamed individuals credited under this contributor:
Anonymous working with Trend Micro's Zero Day Initiative · 5Orange Tsai(@orange_8361) from DEVCORE Research Team working · 3Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningT · 3ChenNan and RanchoIce of Tencent ZhanluLab working with Tren · 2DA-0x43-Dx4-DA-Hx2-Tx2-TP-S-Q from GTSC working with Trend M · 2Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative · 2Jang (Nguyễn Tiến Giang) of StarLabs SG working with Trend M · 2Peter Girnus (gothburz) of Trend Micro's Zero Day Initiative · 2Zero Day Initiative (ZDI)Simon Zuckerbraun working with Trend Micro's Zero Day Initia
02

Narrative reach

— how far this contributor’s records carry an attacker, front door → lights out
1Front door
54reach this stage
→
2Keys to the kingdom
54reach this stage
→
3Lateral reach
51reach this stage
→
4Data at risk
10reach this stage
→
5Lights out
1reach this stage

Furthest any of these records carries an attacker: 5 · Lights out. 10 of 54 narrative-framed records reach data-at-risk or lights-out. (furthest-position idiom, reused from the landing map; the stage mapping is a model output over cited evidence.)

03

Recent highlights

— this contributor’s newest known-exploited records
04

Every record they’re cited in

— all 57, each linked to its cited source

This is the evidence behind every number above. Sorted ransomware-first, then by modeled exploit probability.

CVE-2023-27350PaperCut100%RWKEVCVE-2021-34473Microsoft100%RWKEVCVE-2025-49704Microsoft100%RWKEVCVE-2021-34523Microsoft100%RWKEVCVE-2023-29357Microsoft100%RWKEVCVE-2022-41082Microsoft100%RWKEVCVE-2020-0688Microsoft100%RWKEVCVE-2022-41040Microsoft100%RWKEVCVE-2019-0604Microsoft100%RWKEVCVE-2021-31207Microsoft100%RWKEVCVE-2024-21412Microsoft99%RWKEVCVE-2024-6670Progress93%RWKEVCVE-2025-26399SolarWinds90%RWKEVCVE-2018-8174Microsoft88%RWKEVCVE-2023-24955Microsoft85%RWKEVCVE-2020-3992VMware83%RWKEVCVE-2019-0752Microsoft82%RWKEVCVE-2023-27351PaperCut78%RWKEVCVE-2024-30088Microsoft68%RWKEVCVE-2023-21529Microsoft59%RWKEVCVE-2019-0841Microsoft41%RWKEVCVE-2018-8581Microsoft27%RWKEVCVE-2021-41379Microsoft19%RWKEVCVE-2019-1253Microsoft12%RWKEVCVE-2019-1388Microsoft9%RWKEVCVE-2019-1385Microsoft4%RWKEVCVE-2018-8405Microsoft3%RWKEVCVE-2018-8406Microsoft3%RWKEVCVE-2026-59310Broadcom3%RWKEVCVE-2023-1389TP-Link100%KEVCVE-2024-4885Progress99%KEVCVE-2023-20887VMware98%KEVCVE-2021-33766Microsoft98%KEVCVE-2024-4358Progress97%KEVCVE-2024-7399Samsung92%KEVCVE-2025-6218RARLAB90%KEVCVE-2022-26923Microsoft84%KEVCVE-2021-38406Delta Electronics76%KEVCVE-2014-0780InduSoft75%KEVCVE-2025-04117-Zip67%KEVCVE-2026-0770Langflow64%KEVCVE-2018-8373Microsoft62%KEVCVE-2024-43461Microsoft54%KEVCVE-2024-29988Microsoft45%KEVCVE-2024-35250Microsoft25%KEVCVE-2021-34484Microsoft22%KEVCVE-2019-1297Microsoft22%KEVCVE-2019-0903Microsoft22%KEVCVE-2020-0986Microsoft16%KEVCVE-2023-50224TP-Link16%KEVCVE-2024-38213Microsoft14%KEVCVE-2022-2586Linux10%KEVCVE-2024-38217Microsoft10%KEVCVE-2024-38014Microsoft6%KEVCVE-2024-30040Microsoft4%KEVCVE-2026-50522Microsoft3%KEVCVE-2024-38226Microsoft3%KEV
05

Coverage & confidence

— what this profile claims, and what it does not

Established (cited)

  • Cited in 57 known-exploited records — the list below; every one links to its public source.
  • Catalogued 6 CVE record(s) as the CNA assigner (from CVE.org).
  • Credited as the finder/reporter on 45 record(s) (CVE.org credits).
  • Coverage gaps — stated, not hidden

  • This profile is an aggregation: it asserts only what the listed records already cite — no new external claim about the contributor is made.
  • The TYPE badge and the narrative-stage mapping are editorial (our call), labeled as such, not a sourced fact.